{"id":1225,"date":"2024-05-17T23:46:30","date_gmt":"2024-05-17T21:46:30","guid":{"rendered":"https:\/\/techlance.ddns.net\/?p=1225"},"modified":"2024-05-17T23:47:37","modified_gmt":"2024-05-17T21:47:37","slug":"microsoftin-toukokuun-2024-tietoturvapaivitykset","status":"publish","type":"post","link":"https:\/\/techlance.ddns.net\/en\/microsoftin-toukokuun-2024-tietoturvapaivitykset\/","title":{"rendered":"Microsoftin toukokuun 2024 tietoturvap\u00e4ivitykset"},"content":{"rendered":"<p>Kuvaus: Luokitus: Kriittinen, Ratkaisu: Virallinen korjaus, Hyv\u00e4ksik\u00e4yt\u00f6n kypsyys: M\u00e4\u00e4rittelem\u00e4t\u00f6n, CVSSv3.1: 8.8, CVE:t: CVE-2024-26238, CVE-2024-29994, CVE-2024-29996, CVE-2024-29997, CVE-2024-29998, CVE-2024-29999, CVE-2024-30000, CVE-2024-30001, CVE-2024-30002, CVE-2024-30003, CVE-2024-30004, CVE-2024-30005, CVE-2024-30006, CVE-2024-30007, CVE-2024-30008, CVE-2024-30009, CVE-2024-30010, CVE-2024-30011, CVE-2024-30012, CVE-2024-30014 (+48 muuta liittyv\u00e4\u00e4 CVE:t\u00e4), Yhteenveto: T\u00e4n\u00e4\u00e4n on Microsoftin toukokuun 2024 Patch Tuesday, joka sis\u00e4lt\u00e4\u00e4 tietoturvap\u00e4ivityksi\u00e4 61 virheelle ja kolme aktiivisesti hyv\u00e4ksik\u00e4ytetty\u00e4 tai julkisesti paljastettua nollap\u00e4iv\u00e4haavoittuvuutta. T\u00e4m\u00e4n Patch Tuesdayn ainoa kriittinen haavoittuvuus on Microsoft SharePoint Serverin et\u00e4koodin suorittamisen haavoittuvuus. Haavoittuvuuksien m\u00e4\u00e4r\u00e4 kussakin kategoriassa on seuraava: 17 oikeuksien korottamisen haavoittuvuutta 2 tietoturvaominaisuuksien ohituksen haavoittuvuutta 27 et\u00e4koodin suorittamisen haavoittuvuutta 7 tietojen paljastamisen haavoittuvuutta 3 palvelunestohaavoittuvuutta 4 v\u00e4\u00e4rent\u00e4misen haavoittuvuutta Yhteens\u00e4 61 virhett\u00e4 ei sis\u00e4ll\u00e4 kahta Microsoft Edge -virhett\u00e4, jotka korjattiin 2. toukokuuta ja nelj\u00e4\u00e4, jotka korjattiin 10. toukokuuta. T\u00e4m\u00e4n p\u00e4iv\u00e4n p\u00e4ivityksiss\u00e4 aktiivisesti hyv\u00e4ksik\u00e4ytetyt nollap\u00e4iv\u00e4haavoittuvuudet ovat: CVE-2024-30040 &#8211; Windows MSHTML Platform Security Feature Bypass -haavoittuvuus Microsoft on korjannut aktiivisesti hyv\u00e4ksik\u00e4ytetyn OLE-rajoitusten ohituksen, joka lis\u00e4ttiin Microsoft 365:een ja Microsoft Officeen k\u00e4ytt\u00e4jien suojaamiseksi haavoittuvilta COM\/OLE-ohjauksilta. CVE-2024-30051 &#8211; Windows DWM Core Library -oikeuksien korottamisen haavoittuvuus Microsoft on korjannut aktiivisesti hyv\u00e4ksik\u00e4ytetyn Windows DWM Core Library -virheen, joka tarjoaa SYSTEM-oikeudet. Lyhyt raportti Kasperskylt\u00e4 kertoo, ett\u00e4 \u00e4skett\u00e4iset Qakbot-haittaohjelman kalasteluhy\u00f6kk\u00e4ykset k\u00e4yttiv\u00e4t haitallisia asiakirjoja hyv\u00e4ksi hy\u00f6dynt\u00e4\u00e4kseen virhett\u00e4 ja saadakseen SYSTEM-oikeudet Windows-laitteissa<\/p>\n\n\n\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2024-May\">https:\/\/msrc.microsoft.com\/update-guide\/releaseNote\/2024-May<\/a><\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-techlance wp-block-embed-techlance\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"wp-embedded-content\" data-secret=\"cFGOXnZbMh\"><a href=\"https:\/\/techlance.ddns.net\/en\/microsoft-365\/\">Microsoft 365<\/a><\/blockquote><iframe class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8221;Microsoft 365&#8221; &#8212; Techlance\" src=\"https:\/\/techlance.ddns.net\/microsoft-365\/embed\/#?secret=DsEYTqnp9i#?secret=cFGOXnZbMh\" data-secret=\"cFGOXnZbMh\" width=\"500\" height=\"282\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe>\n<\/div><\/figure>","protected":false},"excerpt":{"rendered":"<p>Kuvaus: Luokitus: Kriittinen, Ratkaisu: Virallinen korjaus, Hyv\u00e4ksik\u00e4yt\u00f6n kypsyys: M\u00e4\u00e4rittelem\u00e4t\u00f6n, CVSSv3.1: 8.8, CVE:t: CVE-2024-26238, CVE-2024-29994, CVE-2024-29996, CVE-2024-29997, CVE-2024-29998, CVE-2024-29999, CVE-2024-30000, CVE-2024-30001, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[11,21,9],"tags":[12,22,15],"class_list":["post-1225","post","type-post","status-publish","format-standard","hentry","category-microsoft-365","category-data-protection","category-security","tag-m365","tag-data-protection","tag-tietoturva"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/posts\/1225","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/comments?post=1225"}],"version-history":[{"count":0,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/posts\/1225\/revisions"}],"wp:attachment":[{"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/media?parent=1225"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/categories?post=1225"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techlance.ddns.net\/en\/wp-json\/wp\/v2\/tags?post=1225"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}